Improper Authorization in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-3160
Published: May 18, 2026
Gitlab Community Edition
GitLab Enterprise Edition
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose Jira issues outside the configured project scope.
The vulnerability exists due to improper access control in Jira integration when enforcing project scope filters. A remote attacker can access Jira issues outside the configured project scope to disclose Jira issues outside the configured project scope.
The integration filter functions only as a display control rather than an enforced access boundary.